Trustbuilder MFA by inWebo

Commvault - Metallic - SAML integration

This documentation describes the process of integrating TrustBuilder MFA as the Identity Provider (IdP) for Commvault's Metallic solution using the SAML 2.0 protocol. This integration enables strong authentication via MFA for accessing Metallic services.

Prerequisites

Before starting, ensure you have the following:

  • An administrator account in TrustBuilder MFA with access to the admin console

  • An administrator account in Metallic with SAML configuration rights

  • The Metallic login URL

Step 1: Configuring TrustBuilder

Create a SAML connector

  1. Login to TrustBuilder administration console.

  2. Go to the Secure Sites tab.

  3. In the "connectors” section, click on Add a connector of type… and select SAML 2.0.

    image-20250305-143538.png
  4. Name your connector (Metallic SAML).

  5. Click on Add to create the connector.
    The SAML connector on TrustBuilder side has been created.

  6. Configure SAML attribute mapping:

    • mail: User mail

    • displayName: Blank space-separated user first and last names

      AD_4nXcUh8oAkSfD9JhRoPrHW7zntSNsekmqUN79wd3Rg0kKxb4sGYq-ThLw0PujcoMsvbrKIiY-cCJ2iEmAkB-CsdLiXXq5yPlUOGxJCBZnRI0gQhKrl04ce-5r3hktBnUrcha-no2AlL6mJWTQuAtT7jI?key=TrJpa8n18t-IQa2fcav0CQ5C
  7. Click on Update to save the configuration.

  8. Download the TrustBuilder metadata in XML format. You will need it later in Metallic configuration.

    image-20230802-134014.png

Create a secure site

  1. Go to the Secure Sites tab.

  2. Click on “Add a Secure Site of type” and select the SAML connector name you configured related to your SAML connector.

  3. In the opening window, set the Secure Site name of your choice and the Called URL to point to your Metallic.

    • The Called URL setting is only used to set a bookmark for the user on My account portal, it has no impact on the security.

  4. Click on Add to save the configuration.

The secure site related to your SAML connector for Metallic, has been successfully created.

Leave the TrustBuilder MFA Admin console open. We will come back to it later.

Step 2: Configuring Metallic

  1. Log in to Metallic as an administrator.

  2. Navigate to Settings > Security > Identity Provider.

    AD_4nXee14-Riyw2kwW4V5dnJyboKvolEaPTwNsE_NPIrh0TtHAHzVLGS8w1x3ekehBGmtsVGVJr37XCeNiw19RGL4OkYANg5JsHohJpBv47t6Zty_5-OhegekCLjZ96lQTkQ0kR7NYFxAmhxpcZiLrsfLc?key=TrJpa8n18t-IQa2fcav0CQ5C
  3. Select SAML Authentication and click Add Identity Provider.

    AD_4nXcLGJyQWkSJ1gGnQ9vpVwzAHUVrtVqAdMjuEcHS6FjGlX7r8PKoGsPw6pvJ5Aq9Efaju6pj7oUWgzBw8y4rVDu3a4LLPzU4jYr-a1hXdOTu_UiLaEmTv0tQNrMOAX05KyJaHFhpoSB4thy5X7rZTqE?key=TrJpa8n18t-IQa2fcav0CQ5C
  4. Give a name to the application: TrustBuilder.

    AD_4nXd1SIjxzvPjid4aZGhXoQbwEao2sroKrniWe-KZvoN3mGRw8_21sKYT5kApl6EPR2hhU8a8nWZ95Ht1IozlSaRlppQa1HYHOAsyaLNYzuUwfXc4Jy-eRfwEtUJyDt-Vsukn6EAA1i_SaRPM-UqSB98?key=TrJpa8n18t-IQa2fcav0CQ5C
  5. Upload the TrustBuilder IdP metadata XML file previously downloaded from TrustBuilder Admin console.

    AD_4nXc2pb7iXSmZOhpW8jI7Mu9U0iBxgqdojg0ePzGt_IBPNXUqcRJBIsD6WD4ZZNeK60dnKCGAaKWXT_7eB25V2upB1I7ePG_BQPtQ2CW_jBaTF3BLVXTV6vj2Y_ENARdnH5VpWzItPEjtuAYkx0jlaaM?key=TrJpa8n18t-IQa2fcav0CQ5C
  6. If not automatically filled, enter the Metallic URL: https://<metallic_url>:443/Identity

    AD_4nXfEUxlMb-hDVHzSE5gztL0GHUjI60qkyuOU2Tn7ptTNJcDxIns3PdJwiau8mvLbNwVug15gGkP99-5OM39iR-1hnQ6xw5U8aLLFNfNyGdedSsEoAP50lnnNVVZ1MlMaj_Upb1UU6aHu-qA_MQ3SHw?key=TrJpa8n18t-IQa2fcav0CQ5C
  7. Configure attribute mapping and enable signed assertion validation.

    AD_4nXcVcl4etrvQ6to_ml5lOhZP92MkGNwAsFn97S9QgEKvzLtKAYwcqgSb69ctFFVcVKrp5T4R42YbGT3TqFCRElQ6retoeOVPOIwaT-UVjiEGgIfjAqew7ZAkCQEwpUOIHbmdWG1TD160Pxd-VyJMZSs?key=TrJpa8n18t-IQa2fcav0CQ5C
    AD_4nXfluDreV5mRipgfXG6YMdk0OwQl6_iWsicicXgntUfOc7IdK8mpLworh9SR5TsbXd0bYy0QB5yLCnT3fh7qzRIvLyZM-9vGnv4XG_F7MUXk828FdBnR29ojSEfwiwa57baDmsJSfm4JhZ6QRLc1kXw?key=TrJpa8n18t-IQa2fcav0CQ5C
    AD_4nXeHNkDzQJwjHazuGhwCV-ISNNQc0t-81cQx2voPFB93rTA0DBk56ZCZIf5GANIEuYcXfk8ABhb3UPbpBUq433_1e0GYmDadHbglwIQeTNi1EnuH5SBgR8957mSbAsUyiUw66TDyOGW7HDgeIpAr0Nc?key=TrJpa8n18t-IQa2fcav0CQ5C
  8. Download the metadata Service Provider metadata file from Metallic.

Leave the Metallic configuration open. We will come back to it later.

Step 3: Providing Metallic SP metadata to TrustBuilder

  1. Go back to the TrustBuilder MFA Admin console.

  2. Edit the SAML connector you created.

  3. Copy the content of Metallic metadata file and paste it into the TrustBuilder SAML connector.

    AD_4nXcMcYGZlUATzElzdWNavuFeS-M_HgZ4qa-lz7a9SC6-ElTwRFQuSHXygm8pm9FdQVdqS3BzmguHzXJWBfTxj1zOr-AsblicEYL6huVWl3NamIROtumlZRWtRtAODaf7XOWcNrkFIDBVov5rhtbN1nI?key=TrJpa8n18t-IQa2fcav0CQ5C
  4. Click on Update to save.

Step 4: Finalizing the setup

  1. Go back to your SAML Metallic configuration.

  2. Click Test Login and attempt authentication.
    ⚠️ This test is required to activate the configuration.

  3. Click Finish.

    AD_4nXfswnh5J2UHLj_EY2sVlM_UB0bS1BKB_ankZkG-piFRqGIgbjN2CX1IzicaOmpTkLjdtoYlewZ-1XF4UoMjLrKHk_paFlfJepque0TjNXzja_HkuM3PZibts_6jy1WaLnpWyOL3fzuA-29thmbvqHQ?key=TrJpa8n18t-IQa2fcav0CQ5C


  4. Navigate to Settings > Security > Identity Provider.

  5. TrustBuilder should appear as an IdP.

    AD_4nXevrhyRzIEUUdP2QvDzMnws2c9nwaM5qK04aeo4xnM1pJyphpNRznvsuo9RKd9HUJC5jZfpKnjSvEGzjOT7F8b9leBonZWyub7t9eYS0jSZAOA9fIU9dqvZBLGGRdUOqZRfXNZTdtxfKQ-sUuNDQ-Q?key=TrJpa8n18t-IQa2fcav0CQ5C
  6. Click on the TrustBuilder IdP and make sure it is enabled.

    AD_4nXfPDOkEfsq6ory_fBJnboAdhVW1TAkmelPWzuPwa-7irEYMcNhS113aWnxGhN1f_b-xbkE-013-iM3Ip8nMUJ0xfymndsleWTfP4kwgN-D4VQcF7-BohUWzbeXnVcL8eFZj335G4_R4JNRuoIaP2w?key=TrJpa8n18t-IQa2fcav0CQ5C

Step 5: Testing

  1. Open a different browser and go to the Metallic login URL.

  2. Enter your username and click Continue.

    AD_4nXdDdpEYbN3dB9_kCQ7ft2IR7uZ1ihctOODBIkftw87XuP3X2BLt1EKGAQtNUF5EmC742JByLJzbD3vmayKJKdey2gwSImDLCm21EwAjhk6P2cY_j6_CjmUVYlzx3uu5Eh7YmY46uGfNgJcnbqTj23M?key=TrJpa8n18t-IQa2fcav0CQ5C
    • You will be redirected to TrustBuilder. After entering your PIN, the user is authenticated successfully.

      image-20250305-151419.png